|
Security of Information
To successfully realise the full potential of electronic transmission of prescription messages it is necessary to enable at least a comparable level of security that is associated with paper-based transactions.
In the digital environment, a Public Key Infrastructure (PKI) ensures that sensitive electronic communications are private and protected. It provides assurances in the identities of the participants in those transactions, and prevents their later denying participating in the transaction.
In the ETP pilot environment the PKI will:
- protect privacy by ensuring that electronic communications are not intercepted and read by unauthorised persons
- assure the integrity of electronic communications by ensuring that they are not altered during transmission
- verify the identity of the parties involved in an electronic transmission
- ensure that no party involved in an electronic transaction can deny their involvement in the transaction
The Certification Authority is a main component of the PKI. It is a trusted third party responsible for issuing digital certificates and managing them throughout their lifetime. Digital certificates are electronic files containing the user's public key and specific identifying information about the user. They are tamper-proof and cannot be forged. Much as a passport office does in issuing a passport, a Certification Authority certifies that the individual granted the digital certificate is who he or she claims to be.
Additional security is provided by the use of NHSnet, the NHS's own private network, and the PPA firewalls where only authorised users can obtain access.
The three pilot consortia are employing different PKI solutions all of which offer the assurances of secure and confidential transmission of information.
PHARMACY2U SECURITY MODEL
SCHLUMBERGERSEMA (FLEXISCRIPT) SECURITY MODEL
TRANSSCRIPT SECURITY MODEL
|